CVE-2023-28856

MEDIUM

Redis - DoS

Title source: llm
STIX 2.1

Description

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

Scores

CVSS v3 5.5
EPSS 0.0034
EPSS Percentile 56.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-617 CWE-20
Status published
Products (5)
debian/debian_linux 10.0
fedoraproject/fedora 36
fedoraproject/fedora 37
fedoraproject/fedora 38
redis/redis < 6.0.19
Published Apr 18, 2023
Tracked Since Feb 18, 2026